[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE-2008-3528 Linux kernel ext[234] directory corruption DoS
From:       Eugene Teo <eteo () redhat ! com>
Date:       2008-09-18 5:41:01
Message-ID: 48D1E9ED.1030809 () redhat ! com
[Download RAW message or body]

The ext[234] filesystem code fails to properly handle corrupted data
structures. With a mounted filesystem image or partition that have
corrupted dir->i_size and dir->i_blocks, a user performing either a read
or write operation on the mounted image or partition can lead to a
possible denial of service.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=459577
http://lkml.org/lkml/2008/9/13/98
http://lkml.org/lkml/2008/9/13/99
http://lkml.org/lkml/2008/9/17/371

The issue is not fixed upstream yet, but the patch has been added to -mm
 tree. I will update this email as soon as I know the commit hashes.
This issue has been allocated with CVE-2008-3528.

Thanks, Eugene
-- 
Eugene Teo / Red Hat Security Response Team
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic